Cobalt Strike Web Services
Many Cobalt Strike features run from their own web server. These services include the system profiler, HTTP Beacon, and Cobalt Strikeās web drive-by attacks. Itās OK to host multiple Cobalt Strike features on one web server.
To manage Cobalt Strikeās web services, go to View -> Web Drive-by -> Manage. Here, you may copy any Cobalt Strike URL to the clipboard or stop a Cobalt Strike web service
Use View -> Web Log to monitor visits to your Cobalt Strike web services.
If Cobalt Strikeās web server sees a request from the Lynx, Wget, or Curl browser; Cobalt Strike will automatically return a 404 page. Cobalt Strike does this as light protection against blue team snooping. The can be configured with the Malleable C2 ā.http-config.block_useragentsā option.
Last updated